← Back to Feed

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

CVE-2026-63078

August 7, 2026 · The Hacker News · Severity: CRITICAL

[v2] PortSwigger researchers built an AI-assisted system called HTTP Terminator that discovered novel HTTP desynchronization techniques and identified a zero-day vulnerability in Apache Traffic Server, tracked as CVE-2026-63078. The system analyzed over 30,000 potential desync vectors across authorized bug bounty programs, identifying roughly 700 vulnerable targets including banks, government systems, and an airport. Key findings include new desync triggers, a dual-matching Content-Length pattern, and a dangling-byte technique that improves response queue poisoning attacks capable of exposing sensitive user data like session cookies. The research also introduced Shared-Parser Confusion, a broader attack class where servers misapply response-processing rules to incoming requests. While HTTP Terminator autonomously generated and validated several techniques, human analysis was still required for the Apache zero-day discovery. PortSwigger has open-sourced HTTP Terminator, which uses Claude AI for document extraction and test-case generation. Newer AI models like GPT-5.6 Sol achieved a 30% success rate in independently rediscovering these techniques, underscoring AI's growing role in complex vulnerability research.

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle , generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server.

Key Takeaways

  • PortSwigger's AI-assisted HTTP Terminator discovered novel HTTP desync techniques and a zero-day in Apache Traffic Server (CVE-2026-63078).
  • The system analyzed 30,000 desync vectors across bug bounty programs, identifying roughly 700 vulnerable targets including banks and government systems.
  • Apache has patched the zero-day — organizations using Apache Traffic Server should update immediately and consider strict HTTP method allow-listing.
☕ Buy a Coffee